Healthy and suitable to depend on. It has a long release history, regular recent releases, strong documentation and tests, and active repository maintenance, though all recent commits came from one contributor and the repository lacks a security policy and explicit workflow permissions.
82%
Total Score
88
100
100
75
All 5 recent commits came from one contributor, leaving the project dependent on a single active individual; organization ownership provides some handoff capacity but does not remove this concentration.
No SECURITY.md or equivalent security policy was found, leaving vulnerability reporting and response expectations less transparent.
The analyzed workflow does not declare top-level token permissions. Although no write permissions were observed, explicit least-privilege settings would provide stronger CI security hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-574383 New plank/laravel-mediable is vulnerable to Stored Cross-Site Scripting (XSS) in versions 0.0.1 - 6.5.0. | 0.0.1 - 6.5.0 | Medium |
AIKIDO-2026-345389 New plank/laravel-mediable is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.0.1 - 6.5.0. | 0.0.1 - 6.5.0 | High |
CVE-2026-49970 plank/laravel-mediable is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 7.0.0. | 0.0.0 - 7.0.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^6.0|^7.2|^8.0 | — | — |
guzzlehttp/psr7 Version ^2.7 | — | — |
league/flysystem Version ^3.29.1 | — | — |
guzzlehttp/guzzle Version ^7.9.1 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.